1. Upon termination of a business associate or employee, a healthcare organization must take 5 steps to protect protected health information (PHI) and electronic PHI (EPHI) according to HIPAA guidelines. These steps include ensuring all PHI and EPHI is returned or destroyed, completing a risk assessment of any PHI or EPHI that cannot be returned or destroyed, implementing safeguards for any retained PHI and EPHI, documenting completion of the termination requirements, and reporting any breaches or improper uses of PHI and EPHI that occur during or after termination.
2. 2
2
5 steps a Healthcare Organization needs to take to protect PHI
and EPHI upon Termination of a Business Associate or Employee
based on HIPAA Guidelines
www.HIPAA-Guard.com
3. 3
3
EPHI-PHI in electronic format
PHI
Protected Health Information (PHI)
Identifiers
The 18 Identifiers Defined by HIPAA are:
Name Medical Record Number
Postal Address Health Plan Beneficiary Number
All elements of dates except year Device Identifiers and their Serial Numbers
Telephone Number
Fax Number Vehicle Identifiers and Serial Number
Email Address Biometric Identifiers (finger and voice prints)
URL Address
IP Address Full face photos and other comparable images
Social Security Number
Account Numbers Any other unique identifying number, code, or
characteristic
License Numbers
4. 4
Business Associates
What is a Business Associate ( BA) ?
A per son o r entity that per forms cer tain functions for a cover ed
entity that involve the use or disclo sur e of pr otected health
infor mation ( PHI) .
PHI is all Individuall y Identifiable Health Infor mation held or
tr ansmitted by a Cover ed Entity or its BA.
A Cover ed Entity is a Health Car e Pr ovider that tr ansmits PHI
Electr onically, a Health Plan, or a H ealth Car e Clear inghouse .